Session

Decade of Ransomware: From Viruses to Machine-Speed Attackers

Ransomware did not begin with Bitcoin or criminal affiliate networks. The first documented case arrived on a floppy disk in 1989. Since then, every generation of attack has reduced the time defenders have to respond.

Viruses automated infection. Worms demonstrated global propagation at machine speed. Cryptocurrency made digital extortion practical, while ransomware-as-a-service transformed specialist crime into an industry. Human-operated groups then turned ransomware from a malicious payload into a complete campaign: acquire access, compromise identities, move laterally, steal cloud data, disrupt operations, and apply pressure. In many modern extortion cases, attackers no longer need to encrypt a single file.

Now AI is removing another constraint: human effort. Recent agentic attacks have explored unfamiliar environments, chained vulnerabilities, recovered from failure, and performed thousands of actions without fatigue. These incidents were not ransomware, but they demonstrate the operating model future extortion campaigns can adopt.

Join Maarten, a 20-year+ MicrosoftMVP, and follow that evolution from 1980s malware to today’s machine-speed attacker. Using real incidents, Maarten will examine why every transition required defenders to expand their approach—from antivirus and backups to identity protection, attack-path analysis, data security, cross-domain detection, and automated containment.

Maarten will connect those lessons to Microsoft Entra, Defender XDR, Sentinel, Purview, Security Exposure Management, and Attack Disruption, before looking toward Project Perception and agentic defense. The conclusion is hopeful: attackers may be gaining speed, but defenders already possess many of the signals and enforcement points required to respond. The next step is connecting them into a system that can act at machine speed while keeping human judgment where it matters most.

After this session, attendees will be able to:

• Explain how ransomware evolved from automated malware into human-operated, service-based, data-driven, and increasingly agentic campaigns.
• Identify why antivirus and backups alone cannot address identity compromise, SaaS data theft, double extortion, and machine-speed attacks—and map Microsoft Security capabilities to those gaps.
• Build a modern response strategy using attack-path context, high-confidence automated containment, data and identity controls, and human governance.


Target audience: Security practitioners, SOC analysts, incident responders, security architects, and security leaders.
Level: 200
Preferred duration: 45–60 minutes.
Format: Strategic-to-technical conference session; no special technical requirements.

Maarten Goet

Microsoft MVP & RD

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top